Head to head · Cms content · October 2026 research run
Payload vs WordPress
WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation. Both do cms content.
Which one, for what
Payload C
Good for Teams that build on Next.js and want the content model in TypeScript, with drafts, versions and localisation in the free core.
Ahead on
- Schema & documentation, 70 against 65
Watch for
49 security advisories in the 12 months to 8 October 2026, 8 critical, 38 of them published since 18 September 2026
Good for Sites that already run WordPress, where an agent drafts posts and uploads media under a Contributor or Author account and a person publishes.
Ahead on
- Agent ergonomics, 74 against 64
- Security & auth, 62 against 57
- Payments & pricing, 60 against 45
- Maintenance & community, 83 against 78
- Transparency & trust, 68 against 62
Also in its favour
- Runs on your own machine
Watch for
Application Passwords have no scopes or expiry. Each one carries every capability of its user
Score by category
| Category | Weight this run | Payload | WordPress | Edge |
|---|---|---|---|---|
| Reliability | 16%20 | 78 | 78 | even |
| Performance | 10%pending | pending | pending | not scored in this run |
| Schema & documentation | 13%16.2 | 70 | 65 | Payload +5 |
| Agent ergonomics | 13%16.2 | 64 | 74 | WordPress +10 |
| Security & auth | 14%17.5 | 57 | 62 | WordPress +5 |
| Payments & pricing | 10%12.5 | 45 | 60 | WordPress +15 |
| Task success | 10%pending | pending | pending | not scored in this run |
| Maintenance & community | 7%8.8 | 78 | 83 | WordPress +5 |
| Transparency & trust | 7%8.8 | 62 | 68 | WordPress +6 |
| Negative events | ≤15 | -10 | -5 | |
| Total | 55.2 · C | 64.8 · B |
Facts side by side
| Fact | Payload | WordPress |
|---|---|---|
| Kind | HTTP API | HTTP API |
| Vendor | Payload CMS, Inc. (Figma) | WordPress.org (open-source project) |
| Hosted endpoint | no (local only) | no (local only) |
| Transports | HTTP, Streamable HTTP | HTTP, stdio |
| Auth | API key | API key |
| Pricing | Free | Free |
| x402 | no | no |
| Licence | MIT for the core and the official packages. Enterprise add-ons are sold separately through sales | GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too |
| Read-only variant documented | no | no |
| llms.txt | yes | yes |
| Last release | 2026-09-23 | 2026-10-06 |
| Terms last updated | no document linked | no document linked |
| Privacy policy last updated | 2024-03-28 | no date given |
| Customer content may train models | ||
| Terms restrict automated access | ||
| Terms restrict benchmarking | ||
| Terms or service can change without notice | ||
| Arbitration or class-action waiver | ||
| Popularity | 45k stars, 1.1M npm/wk | 21k stars |
Verdicts
Payload
Payload generates REST, GraphQL and MCP interfaces from one typed config, with drafts, restorable versions and per-key MCP permissions in the free MIT core. The security record is the limit. The vendor published 49 advisories in 12 months, 8 of them critical, so an install older than 3.90.0 is exposed. No OpenAPI file is published.
WordPress
The REST API is part of core, and a post created without a status is saved as a draft with revisions kept on the owner's server. Application Passwords carry no scopes, so limits come only from the user's role. Revisions can be read and deleted but not restored over REST, and a critical flaw was fixed on 22 September 2026.
Before you call either
Payload
- Check the installed version first. Anything below 3.90.0 carries published critical advisories, so ask the owner to upgrade before writing
- Send REST keys as
Authorization: {collection-slug} API-Key {key}and MCP keys asAuthorization: Bearer {key}. The two key kinds are separate - To publish, set
_status: 'published'in the data. Thedraftparameter only relaxes validation and chooses where an update is written - Upload files with multipart POST to the upload collection, with other fields as JSON in
_payload. No MCP upload tool is documented - Roll back with
POST /api/{collection-slug}/versions/:idafter listing versions. Versions exist only where the collection config enables them
WordPress
- Ask the owner for a dedicated user with the lowest role that fits. A Contributor can draft and edit its own posts but can't publish them
- Send the Application Password as Basic auth over HTTPS only. Core disables Application Passwords on plain HTTP outside a local environment
- Upload a file with POST
/wp-json/wp/v2/mediafirst, then setfeatured_mediaor reference the returned URL in the post content - To roll back, GET
/wp/v2/posts/<id>/revisions/<rev>?context=editand POST its title and content to the post. There's no restore route - Pass
_fields=id,status,link,modifiedon lists and read X-WP-TotalPages.per_pagestops at 100
Questions
Which is better for AI agents, Payload or WordPress?
WordPress scores 64.8 (B) on agent readiness against Payload's 55.2 (C), and leads in 5 of 7 scored categories. Payload leads on schema & documentation.
Do Payload and WordPress need an API key?
Both need an API key.
Can an agent call Payload and WordPress without installing anything?
No hosted endpoint is listed for Payload. WordPress runs on your own machine, with no hosted endpoint listed.
Are Payload and WordPress open source?
Yes. Payload is open source (MIT for the core and the official packages. Enterprise add-ons are sold separately through sales). WordPress is open source (GPL-2.0-or-later. The MCP Adapter plugin is GPL-2.0-or-later too).
Other comparisons with Payload or WordPress
- Contentstack vs Payload
- Contentstack vs WordPress
- DatoCMS vs Payload
- DatoCMS vs WordPress
- Directus vs Payload
- Directus vs WordPress
- Ghost vs Payload
- Ghost vs WordPress
- Payload vs Sanity
- Payload vs Storyblok
- Payload vs Strapi
- Payload vs Webflow
- Sanity vs WordPress
- Storyblok vs WordPress
- Strapi vs WordPress
- Webflow vs WordPress
Machine-readable
- This page as Markdown
/compare/payload-vs-wordpress.md· slim.min.md· JSON.json(or sendAccept: text/markdown) - Each listing in full
/api/v1/tools/payload.json·/api/v1/tools/wordpress.json - From a terminal
anchor compare payload wordpress(the CLI) - Over MCP
compare_tools {"a": "payload", "b": "wordpress"}at/mcp, no key